24 minPiotr Ryciak - Vibe Check: Security Failures in AI-Assisted IDEs | [un]prompted 2026
unprompted
- 工作區信任模型失效的三個原因:工作區應預設拒絕信任,但大多數工具預設允許;不受信任的儲存庫應禁用所有代碼執行功能,但許多工具只有部分功能受限;配置變更時應重新提示信任,但當前多數工具只在初次信任時檢查一次,導致後續配置被投毒後仍可執行。
- 四類主要攻擊模式各有繞過防禦的手段:零點擊攻擊繞過信任檢查(MCP 伺服器在沙箱外初始化、discover 命令在信任對話前執行);提示注入通過目錄名稱、文件名誘騙代理而非配置;配置投毒利用信任持久性在後續 git pull 時自動執行;沙箱機制本身存在繞過漏洞。
- 不同供應商對同一漏洞的認定標準不一致:Anthropic 認為信任持久性是「安全與可用性的平衡」,OpenAI Codeex 標記為「資訊類錯誤」,但 Cursor 同樣漏洞被分配 CVE 編號,導致用戶面臨真實風險卻無統一指導。
![Gadi Evron - Closing Words | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FNikR9PuB24U%2Fhqdefault.jpg&w=3840&q=75)
![Billy Norwood - Establishing AI Governance Without Stifling Innovation | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2Fsh9LpVM1QBM%2Fhqdefault.jpg&w=3840&q=75)
![Ragini Ramalingam - Enterprise AI Governance at Snowflake | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FRF4gR5uviv0%2Fhqdefault.jpg&w=3840&q=75)
![Chase Hasbrouck - Three Phases of AI Adoption | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FUOtVmYR0mRg%2Fhqdefault.jpg&w=3840&q=75)
![Rob T. Lee - SIFT-FIND EVIL! I Gave Claude Code R00t on DFIR SIFT Workstation | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FOsUg3TlAqjQ%2Fhqdefault.jpg&w=3840&q=75)
![Mika Ayenson - "Can You See What Your AI Saw?" | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FcEbPSQaSLXM%2Fhqdefault.jpg&w=3840&q=75)
![Mohamed Nabeel - Detecting GenAI Threats at Scale with YARA-Like Semantic Rules | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FPZYtJL6TCwo%2Fhqdefault.jpg&w=3840&q=75)
![Aaron Grattafiori & Skyler Bingham - Tenderizing the Target | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FnRH_rdW7EL8%2Fhqdefault.jpg&w=3840&q=75)
![Matt Maisel - Hooking Coding Agents with the Cedar Policy Language | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2Fm6pzrqFJ6hE%2Fhqdefault.jpg&w=3840&q=75)
![Carl Hurd - Glass-Box Security: Operationalizing Mechanistic Interpretability | [un]prompted 2026](/_next/image?url=https%3A%2F%2Fi.ytimg.com%2Fvi%2FJZlaijmG-Ng%2Fhqdefault.jpg&w=3840&q=75)


















